← Back

Cybersecurity by department

Cybersecurity isn't just an IT thing.

Every area of your company has its part — and its risk. Here's what each one needs to be NIS2-ready, and how we set it up from Tria, speaking their language.

Cybersecurity is cross-functional. It isn't solved inside one department: it holds up through the joint work of all of them. A single open door —in any area— is enough to compromise the whole company.

Department

Management

Whoever leads is who answers

This is what's at stake in the boardroom, what you need under control to be NIS2-ready, and how we set it up from Tria.

Oversight and governance
Risk

Cybersecurity is fully delegated to IT and management doesn't oversee it. If there's an incident or an inspection, no one answers with judgment or can prove anything was decided.

◆ In a NIS2-ready setup, the management body is responsible for approving and overseeing the measures.

What you need

Take on oversight: approve the policies, review risk regularly and assign owners and resources.

How we set it up
  • Security committee with minutes and calendar
  • Security policy approved by management
  • Quarterly risk dashboard
  • Responsibility map (RACI)
  • vCISO who runs the committee
Management training
Risk

A management that doesn't understand the risk decides blindly and can't demonstrate due diligence.

◆ Training of the management bodies is an explicit requirement in NIS2.

What you need

Specific, non-technical training: what your obligations are, what to ask and how to read risk.

How we set it up
  • Training session for management / board
  • Periodic executive briefing
  • Training record as evidence
Investment and priorities
Risk

You invest blindly —or not at all— and buy tools that don't reduce real risk.

What you need

A risk-prioritised plan and a defensible budget, tied to business impact.

How we set it up
  • Prioritised security master plan
  • Business case: cost of an incident vs. preventing it
  • 12-24 month roadmap
Response and accountability
Risk

In a serious incident, accountability falls on management and can't be fully passed on. Without evidence of diligence, you're exposed to the fine.

What you need

Being able to prove you did what was reasonable: documented decisions, a response plan and timely notification.

How we set it up
  • Incident response plan with roles and deadlines
  • Notification procedure
  • Due-diligence file ready for inspection
Continuity and crisis
Risk

When something happens, no one knows who decides what; you improvise in front of clients and media and lose time and money.

What you need

A continuity and crisis plan with management inside: what stops, who decides and what's communicated.

How we set it up
  • Business continuity plan
  • Crisis and communication protocol
  • Tabletop exercise with the committee
Reputation and contracts
Risk

An incident —or not being able to prove your level— closes contracts and damages the brand. Large clients already demand guarantees.

What you need

Turning security into an argument: proving your level to clients and in tenders.

How we set it up
  • Trust dossier for clients
  • Certification readiness (ISO 27001 / ENS)
  • Fast answers to client due diligence

Department

IT / Systems

Who keeps operations running

We're not here to teach you your job: we give you the prioritised framework, evidence ready to go and take the documentation load off you. This is what to have NIS2-ready.

Access and identity
Risk

Shared accounts, weak passwords, ex-employees with access, admins with no control. A stolen login is the direct way in.

What you need

Identity and access under control: MFA, least privilege, fast joiners/leavers and periodic review.

How we set it up
  • Access policy
  • MFA / FIDO2 deployed
  • Identity management and privilege review
  • Joiner-mover-leaver procedure
Backups and recovery
Risk

Backups that aren't tested or with no offline copy. Against ransomware, there's no way back.

What you need

3-2-1 backups with tested restores and defined recovery times (RTO/RPO).

How we set it up
  • 3-2-1 backup strategy
  • Periodic restore tests
  • RTO/RPO defined per system
Vulnerabilities and patching
Risk

Unpatched systems exposed to the internet. Known flaws get exploited.

What you need

Inventory, patching and vulnerability management prioritised by criticality.

How we set it up
  • Asset inventory
  • Patching cycle
  • Vulnerability scanning
  • Hardening (CIS)
Monitoring and detection
Risk

An attacker gets in and no one notices for weeks. Without logs there's no way to know what happened.

What you need

Centralised logs, alerts and the ability to detect and respond.

How we set it up
  • Log centralisation
  • Alerts and thresholds
  • Technical response guide
  • (Optional) EDR / managed SOC
Network and email
Risk

A flat network (everything connected to everything) and unprotected email: phishing and lateral movement.

What you need

Segmentation, email protection and safe browsing.

How we set it up
  • Network segmentation
  • SPF / DKIM / DMARC
  • Anti-phishing email filtering
  • Device policies
Evidence and audit
Risk

Everything works but you can't prove it. Audits and clients ask for evidence that doesn't exist.

What you need

Document the controls and leave traceable evidence.

How we set it up
  • Controls framework (CIS / ISO 27002 / ENS) mapped
  • Evidence repository
  • Status report

Department

HR

Who looks after people

You handle the most sensitive data and you're key against fraud. This is what to keep under control and how we set it up, without slowing your day-to-day.

Sensitive staff data
Risk

Payroll, health and candidate data accessible too widely. A leak here is serious and highly fineable.

What you need

Minimum access, clear retention periods and legal basis.

How we set it up
  • File access policy
  • Retention calendar
  • HR processing register
Employee lifecycle
Risk

Whoever leaves still has access; whoever joins gets it late or too broad.

What you need

Onboarding and offboarding with real access provisioning and revocation.

How we set it up
  • Joiner-mover-leaver procedure
  • Onboarding / offboarding checklist
  • Coordination with IT
Awareness and phishing
Risk

The team is the number-one way in; one click takes the company down.

What you need

Ongoing training and simulations to reduce human error.

How we set it up
  • Annual training plan
  • Simulated phishing campaigns
  • Plain-language materials
  • Improvement metrics
Whistleblowing channel
Risk

A missing or poorly run channel exposes the company and whistleblowers.

◆ A whistleblowing channel is mandatory for many companies (Spanish Law 2/2023).

What you need

A secure, confidential and well-run channel.

How we set it up
  • Channel setup / review
  • Handling procedure
  • Training for handlers
Workplace monitoring
Risk

Monitoring without informing or disproportionately leads to fines and conflict.

What you need

Informing and keeping control proportionate (access, cameras, devices).

How we set it up
  • Acceptable use policy
  • Employee information
  • Proportionality review
Security culture
Risk

Security is seen as a brake and the team dodges it.

What you need

Making security part of the culture, not a punishment.

How we set it up
  • Security in onboarding
  • Internal communication
  • Security champions per area

Department

Finance / Administration

The direct target of fraud

You're where the money is, and that makes you the preferred target. This is what to reinforce and how we set it up so fraud doesn't get through.

Payment fraud (BEC / CEO)
Risk

Fake emails ordering urgent transfers or account changes. Just one that gets through and the money is gone.

What you need

Double verification of payments and of bank-detail changes.

How we set it up
  • Payment verification procedure
  • Segregation of duties
  • Dual signature / authorisation
  • Specific team training
Financial and banking data
Risk

Access to banking and payment data with no control; credential theft.

What you need

Restricted access, MFA on banking and protection of payment data.

How we set it up
  • MFA on banking and ERP
  • Access control
  • Encryption of financial data
  • Payment-data policy
Continuity of billing and payments
Risk

If the system goes down, you can't invoice, collect or pay. The business stops.

What you need

Continuity of critical financial processes.

How we set it up
  • Critical process identification
  • Contingency plan
  • ERP backups
Invoicing and traceability
Risk

Non-compliant or tamperable invoicing systems.

What you need

Compliant, complete and traceable invoicing.

How we set it up
  • Alignment with e-invoicing / anti-fraud (Verifactu)
  • Invoice traceability
  • System access control
Investment and cyber insurance
Risk

You pay for cyber insurance that doesn't cover what you think, or you don't size the investment.

What you need

Sizing the investment and understanding the real coverage.

How we set it up
  • Security business case
  • Cyber-insurance policy review
  • Requirements the insurer demands
Third parties that touch your money
Risk

Dependence on payment platforms and third parties with no control.

What you need

Assessing the security of financial third parties.

How we set it up
  • Payment-provider vetting
  • Security clauses
  • Access review

Department

Procurement / Suppliers

The supply-chain door

An insecure supplier is your way in, and you're the supplier others audit. This is what to control in both directions.

Supply-chain risk
Risk

An insecure supplier is your way in: their breach is your breach.

◆ NIS2 makes you responsible for the security of your supply chain.

What you need

Knowing and controlling your suppliers' risk.

How we set it up
  • Critical-supplier inventory
  • Security questionnaire
  • Vetting criteria
Contracts with security
Risk

Contracts with no security clauses or defined responsibilities.

What you need

Security clauses and service levels in contracts.

How we set it up
  • Standard security clauses
  • Service-level agreements (SLA)
  • Incident-notification requirement
Third-party access
Risk

Suppliers with broad, permanent access to your systems.

What you need

Minimum, temporary and reviewed access.

How we set it up
  • Third-party access policy
  • Temporary access
  • Periodic review and logging
Dependence on critical suppliers
Risk

Depending on a cloud / SaaS with no plan B: if it falls, you fall.

What you need

Assessing concentration and having alternatives.

How we set it up
  • Dependency analysis
  • Exit / continuity plan
  • Backup and SLA
Agile vetting
Risk

Requiring security slows procurement and annoys the business.

What you need

A proportionate, fast vetting process.

How we set it up
  • Questionnaire by risk level
  • Express vetting for low risk
  • Approved-supplier repository
Being the audited supplier
Risk

A large client audits you and you have no answers: you lose the contract.

What you need

Having your own evidence ready for when you're audited.

How we set it up
  • Client security dossier
  • Answers to questionnaires
  • Certifications

Department

Operations

Who can't stop

An incident here isn't an IT problem: it's a delivery and deadline problem. This is what to secure so operations hold.

Operational continuity
Risk

An incident stops production or the service and you miss client deadlines.

What you need

Knowing which processes can't stop and how to sustain them.

How we set it up
  • Business impact analysis (BIA)
  • Continuity plan
  • Manual / temporary alternatives
Critical assets and processes
Risk

There's no inventory of what's critical; you protect blindly.

What you need

Identifying and prioritising critical assets and processes.

How we set it up
  • Critical-asset inventory
  • Dependency map
  • Prioritisation by impact
Industrial systems (OT)
Risk

Machinery and industrial systems connected and unprotected.

What you need

Segmenting and protecting the OT environment (where applicable).

How we set it up
  • IT / OT segmentation
  • OT access control
  • Specific monitoring
Operational incidents
Risk

When it happens, you improvise and take long to recover.

What you need

A response and operational-recovery plan.

How we set it up
  • Response plan
  • Roles and escalation
  • Operational drills
Suppliers and logistics
Risk

Dependence on logistics and service providers: their failure stops you.

What you need

Continuity in the chain that supplies you too.

How we set it up
  • Contingency plan for critical suppliers
  • Alternatives
  • Coordination with Procurement
Operational data
Risk

Loss or tampering of production or order data.

What you need

Integrity and backups of operational data.

How we set it up
  • Backups of operational systems
  • Integrity control
  • Role-based access

Department

Marketing / Sales

The heavy data user

Your CRM and prospecting tools are pure personal data. This is what to tidy up to capture leads without fines — and how to turn compliance into a sales argument.

CRM full of personal data
Risk

The whole CRM is personal data; a breach exposes your entire client base.

What you need

Legal basis, access and CRM cleanup.

How we set it up
  • CRM use policy
  • Access control
  • Data cleanup and minimisation
  • Processing register
Prospecting and bought lists
Risk

Buying or enriching lists with no control is a high fine risk.

What you need

Prospecting with a legal basis and traceability of the data's origin.

How we set it up
  • Compliant prospecting criteria
  • Origin / consent record
  • Data-provider review
Consent and communications
Risk

Sending commercial communications without valid consent.

What you need

Consent and opt-outs handled correctly.

How we set it up
  • Consent management
  • Double opt-in
  • Opt-out management
  • Compliant templates
Website, cookies and forms
Risk

A site with non-compliant cookies and forms: the first thing an inspection looks at.

What you need

Compliant cookies, forms and notices.

How we set it up
  • Compliant cookie banner
  • Legal text for forms
  • Reviewed privacy policy
Marketing tools
Risk

Dozens of tools (ads, email, analytics) processing data with no control.

What you need

Knowing which tools process data and with what guarantees.

How we set it up
  • Tool inventory
  • Processor agreements
  • International-transfer review
Compliance as a sales argument
Risk

Losing sales for not being able to prove security — or not leveraging it when you have it.

What you need

Using compliance as a commercial lever.

How we set it up
  • Trust seal / dossier
  • Talking points for the sales team
  • Answers to client due diligence

Not sure where to start?

The free check-up tells you in 2 minutes what applies to you and where to begin. No sign-up, no data required.

Take the free check-up →